Skip to main content

OpenBLD Plus

OpenBLD Plus is a protective DNS platform for organizations that need control, visibility, analytics, and professional support beyond a public DNS resolver.

It extends the OpenBLD security model with corporate deployment options, organization-specific policies, centralized DNS security events, infrastructure integrations, and security reporting.

OpenBLD Free protects everyone. OpenBLD Plus protects organizations.

Who OpenBLD Plus is for

OpenBLD Plus is designed for:

  • companies and corporate networks;
  • organizations using Active Directory;
  • security and infrastructure teams;
  • offices, branches, VPN, and remote users;
  • MSP and MSSP providers;
  • organizations with privacy or data residency requirements;
  • companies that need visibility into DNS activity and threats.

What OpenBLD Plus provides

Protective DNS

OpenBLD Plus helps detect and block:

  • malware and phishing domains;
  • known malicious resources;
  • suspicious domains and DGA-like activity;
  • DNS tunneling indicators;
  • unwanted or organization-specific resources.

Organizations can use custom allowlists, blocklists, and security policies.

DNS visibility and analytics

OpenBLD Plus provides centralized insight into corporate DNS activity:

  • DNS request volume and peak load;
  • requested and blocked domains;
  • suspicious and DGA activity;
  • affected clients;
  • report-only findings;
  • operational DNS issues and recurring threats.

Corporate DNS integration

OpenBLD Plus can work with the existing DNS infrastructure instead of replacing it.

Supported deployment scenarios may include:

  • Active Directory DNS;
  • internal DNS zones;
  • corporate upstream resolvers;
  • split DNS and custom routing;
  • offices, branches, VPN, and remote users;
  • dnsdist-based infrastructure.

Centralized security events

DNS security events can be sent to centralized storage, monitoring, and analytics systems.

Integration options may include:

  • ClickHouse;
  • VictoriaLogs;
  • Grafana;
  • Prometheus-compatible monitoring;
  • syslog and SIEM systems.

Privacy and data residency

With an On-Premise deployment, DNS traffic, security events, and analytics data can remain inside the customer infrastructure.

This is suitable for organizations with strict privacy, compliance, or data residency requirements.

Deployment options

Managed Cloud

OpenBLD operates and maintains the DNS security infrastructure.

This option is suitable for organizations that need:

  • managed protective DNS;
  • organization-specific policies;
  • centralized monitoring and analytics;
  • infrastructure updates;
  • technical support.

On-Premise

OpenBLD Plus is deployed inside the customer infrastructure.

The organization retains control over:

  • DNS traffic;
  • logs and analytics data;
  • integrations;
  • infrastructure;
  • retention policies.

OpenBLD provides deployment assistance, configuration, updates, and professional support.

Dedicated DNS

Dedicated DNS is a simpler option for organizations that need more than the public OpenBLD Free service but do not require a complete On-Premise deployment.

It may include:

  • dedicated endpoints;
  • corporate IP and network ranges;
  • custom policies;
  • monitoring and basic analytics;
  • priority support.

Report Only mode

OpenBLD Plus can be introduced without immediately blocking DNS requests.

In Report Only mode, the platform analyzes DNS traffic and records security findings while allowing requests to continue.

This helps identify:

  • malicious and suspicious domains;
  • DGA-like activity;
  • affected clients;
  • recurring threats;
  • DNS configuration problems;
  • operational anomalies.

Report Only mode provides a low-risk way to evaluate OpenBLD Plus before enabling enforcement.

OpenBLD Plus Security Pilot

A Security Pilot evaluates OpenBLD Plus using real DNS traffic from the organization.

A typical pilot includes:

  1. DNS infrastructure and traffic-flow review;
  2. Report Only deployment;
  3. observation and analysis;
  4. security and operational findings;
  5. recommendations;
  6. production deployment proposal.

The resulting report can provide an executive overview, DNS traffic statistics, threat findings, affected clients, operational risks, and recommended next steps.

OpenBLD Free and OpenBLD Plus

CapabilityOpenBLD FreeOpenBLD Plus
Public protective DNS
No required registration
Custom security policies
Corporate DNS integration
Centralized DNS analytics
Report Only mode
Managed or On-Premise deployment
Professional support
SLA options
Customer-controlled data storage

OpenBLD Free remains free and is not intentionally degraded to force users to upgrade, subject only to necessary usage limits to prevent abuse.

Organizations use OpenBLD Plus for additional corporate capabilities, deployment options, integrations, analytics, reporting, and professional support.

Request OpenBLD Plus

OpenBLD Plus is available for pilot projects, managed deployments, dedicated DNS, and On-Premise installations.

To discuss your infrastructure and requirements: